<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/121326#M22540</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Check Point&amp;nbsp; TAC came with more information:&lt;BR /&gt;&lt;EM&gt;"Indeed the hotfix should be integrated into the upcoming Jumbos, currently, we don't have an exact ETA but you can follow&amp;nbsp;sk165456 for PMTR-69435.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sk173933&amp;nbsp;was created for this issue, just in case you wish to follow up further."&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;so finally the hotfix "&lt;SPAN&gt;fw1_wrapper_HOTFIX_R80_40_JHF_T118_865_MAIN_GA_FULL.tgz" really solved the issue!&lt;BR /&gt;some final words from TAC about the root cause would be fantastic, to understand the issues more precise!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jun 2021 05:55:44 GMT</pubDate>
    <dc:creator>Thomas_Eichelbu</dc:creator>
    <dc:date>2021-06-16T05:55:44Z</dc:date>
    <item>
      <title>Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120722#M22443</link>
      <description>&lt;P&gt;Hello fellow CheckMates.&lt;BR /&gt;&lt;BR /&gt;We have encountered some strange issues after upgrading R80.40 above Take93/Take94.&lt;BR /&gt;We see that ICMP is NOT passing through&amp;nbsp; the gateway, it starts to work ONLY after a TCP packet has been sent ...&lt;BR /&gt;This happens in local attached networks, over routed networks and also over VPN ...&amp;nbsp;&lt;BR /&gt;It doesnt matter if SecureXL is ON/OFF ...&lt;BR /&gt;Regardless if openserver or appliance&lt;BR /&gt;&lt;BR /&gt;what we see:&lt;BR /&gt;only an echo / never a replay&lt;/P&gt;&lt;DIV&gt;[vs_0][fw_4] eth4:&lt;SPAN&gt;i&lt;/SPAN&gt;[44]: 172.XX.66.228 -&amp;gt; 172.ZZ.10.43 (ICMP) len=96 id=30804&lt;BR /&gt;ICMP: type=8 code=0 echo request id=64388 seq=0&lt;BR /&gt;[vs_0][fw_4] eth4:&lt;SPAN&gt;I&lt;/SPAN&gt;[44]: 172.XX.66.228 -&amp;gt; 172.ZZ.10.43 (ICMP) len=96 id=30804&lt;BR /&gt;ICMP: type=8 code=0 echo request id=64388 seq=0&lt;BR /&gt;[vs_0][fw_5] eth4:&lt;SPAN&gt;i&lt;/SPAN&gt;[44]: 172.XX.66.228 -&amp;gt; 172.ZZ.10.43 (ICMP) len=96 id=30829&lt;BR /&gt;ICMP: type=8 code=0 echo request id=64388 seq=1&lt;BR /&gt;[vs_0][fw_5] eth4:&lt;SPAN&gt;I&lt;/SPAN&gt;[44]: 172.XX.66.228 -&amp;gt; 172.ZZ.10.43 (ICMP) len=96 id=30829&lt;BR /&gt;ICMP: type=8 code=0 echo request id=64388 seq=1&lt;/DIV&gt;&lt;P&gt;&lt;BR /&gt;We see only small "i" and big "I" ... never small "o", big "O"&lt;BR /&gt;We know this destination is ALIVE.&lt;BR /&gt;When we send an TCP packet, immediatley an ARP request is made and an ARP entry is created then the ICMP works!!!&lt;BR /&gt;This happens also over VPN!&lt;BR /&gt;On the DESTINATION IP we checked with tcpdump, NOTHING was received until the first TCP SYN was sent, then the ICMP followed!&lt;BR /&gt;No drops seen with fw ctl zdebug / no drops seen on Smartlog&lt;BR /&gt;When the ping works, is sometimes stops after 60 seconds! (ARP timeout = 60?)&lt;BR /&gt;This happens mostly to "silent" device which do not have&amp;nbsp; permanent TCP sessions runnings becasue TCP "heals" the connection.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Several CP Cases are ongoing, and alot of R80.40 installations are affected ...&amp;nbsp;&lt;BR /&gt;And we had numerous remote sessions with TAC to proove the issue is real and not a&amp;nbsp; hoax.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;yes there is this SK for example ...&lt;BR /&gt;&lt;A href="https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupportcenter.checkpoint.com%2Fsupportcenter%2Fportal%3FeventSubmit_doGoviewsolutiondetails%3D%26solutionid%3Dsk152093&amp;amp;data=04%7C01%7CHerbert.Putz%40kapsch.net%7C5f9b5c273b5b41dc029708d92b0aa40c%7C5f9ce5277e3e4e83a8a4b6c848f85ab5%7C1%7C0%7C637588146983765051%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;amp;sdata=D%2BxM2bPqIbJLjmEOMBTmfdRATJmEeTh2qHTVXO%2Bi55Q%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;When SecureXL is enabled, no ARP is sent and traffic fails (checkpoint.com)&amp;nbsp;&lt;SPAN&gt;sk152093&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;it decribes the exact opposite ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;what is your experience from the field?&lt;BR /&gt;&lt;BR /&gt;best regards&lt;BR /&gt;Thomas&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 08:28:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120722#M22443</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-06-09T08:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120852#M22459</link>
      <description>&lt;P&gt;We experienced the same problem (only on one of our multiple clusters) and opened a TAC case at April 9th. It took a long time, but R&amp;amp;D finally said they found the root cause:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;May 28th.:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Good news, we managed to find out the root cause of the issue which was an update for the PBR and ABR functionality that got integrated into take_92. You can refer to this documentation&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165456" target="_blank" rel="noopener" shape="rect"&gt;sk165456&lt;/A&gt; "Jumbo Hotfix Accumulator for R80.40 (R80_40_jumbo_hf) " for further information.&lt;BR clear="none" /&gt;&lt;BR clear="none" /&gt;A fix for this issue is already under development and should be integrated into the coming Jumbos.&lt;BR clear="none" /&gt;&lt;BR clear="none" /&gt;To monitor the fix implementation, you can use this fix ID "&amp;nbsp;PRJ-26756 " to know whether it will be integrated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;June 8th:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The fix was compiled successfully and the fix will be integrated into all the affected versions ( R80.40 and R81 ).&lt;BR clear="none" /&gt;A port fix for R80.40 take_118 has been already requested and I will keep you informed as soon as possible whether it is ready.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 13:52:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120852#M22459</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-06-10T13:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120863#M22464</link>
      <description>&lt;P&gt;That explanation makes perfect sense as packets disappearing after iI and not reentering o means that the Gaia OS itself "ate" the packet, and since PBR/ABR is part of the Gaia OS that tracks.&amp;nbsp; I mentioned this in my &lt;A href="https://community.checkpoint.com/docs/DOC-2739" target="_self"&gt;speech at CPX 2018&lt;/A&gt; and called it the "roach motel" scenario, and also covered troubleshooting this extensively in my Max Capture video series.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 15:50:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120863#M22464</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-06-10T15:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120916#M22474</link>
      <description>&lt;P&gt;Hi Tobias,&lt;BR /&gt;&lt;BR /&gt;yes Check Point TAC said a custom hotfix on top of HFA118 is on its way ... it should be available by end of this week.&lt;BR /&gt;In the meantime we were told to&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;+ switch to Usermode FW&lt;BR /&gt;+ create static ARP entries&lt;BR /&gt;&lt;BR /&gt;well i have not tried this so far as the most costumer enviroments are not meant as playground for guessing games ...&amp;nbsp;&lt;BR /&gt;we will see!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 08:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120916#M22474</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-06-11T08:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120920#M22477</link>
      <description>&lt;P&gt;Hi Timothy,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;it seems this Packet Injector from&amp;nbsp;&lt;SPAN&gt;sk110865 only works on R80.10 and not on versions like R80.30 and up?&lt;BR /&gt;is there are newer version?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 08:29:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120920#M22477</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-06-11T08:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120945#M22484</link>
      <description>&lt;P&gt;&lt;STRONG&gt;pinj&lt;/STRONG&gt; is not supported past R80.10 due to the SecureXL overhaul in R80.20.&amp;nbsp; Alternative packet generators that are built-in to Gaia are &lt;STRONG&gt;tcptraceroute&lt;/STRONG&gt; and &lt;STRONG&gt;hping2&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 12:47:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/120945#M22484</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-06-11T12:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/121139#M22525</link>
      <description>&lt;P&gt;Hotfix is available through TAC now.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;U&gt;&lt;STRONG&gt;Hotfix information&lt;/STRONG&gt;&lt;/U&gt;:&lt;BR clear="none" /&gt;&amp;nbsp;&lt;BR clear="none" /&gt;&lt;STRONG&gt;Name:&lt;/STRONG&gt;&amp;nbsp;fw1_wrapper_HOTFIX_R80_40_JHF_T118_865_MAIN_GA_FULL.tgz&lt;BR clear="none" /&gt;&lt;STRONG&gt;MD5SUM:&lt;/STRONG&gt;&amp;nbsp;c90b532396928d2b37ec0a0f0b9e4ed5&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 12:22:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/121139#M22525</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-06-14T12:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/121141#M22526</link>
      <description>&lt;P&gt;Hello Tobias,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;yes true i have received the same information today ... tomorrow we try it.&lt;BR /&gt;then we will see if it resolves all issues!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 12:27:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/121141#M22526</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-06-14T12:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ICMP issues in R80.40 with hotfixes greater Take 94.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/121326#M22540</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Check Point&amp;nbsp; TAC came with more information:&lt;BR /&gt;&lt;EM&gt;"Indeed the hotfix should be integrated into the upcoming Jumbos, currently, we don't have an exact ETA but you can follow&amp;nbsp;sk165456 for PMTR-69435.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sk173933&amp;nbsp;was created for this issue, just in case you wish to follow up further."&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;so finally the hotfix "&lt;SPAN&gt;fw1_wrapper_HOTFIX_R80_40_JHF_T118_865_MAIN_GA_FULL.tgz" really solved the issue!&lt;BR /&gt;some final words from TAC about the root cause would be fantastic, to understand the issues more precise!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 05:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Strange-ICMP-issues-in-R80-40-with-hotfixes-greater-Take-94/m-p/121326#M22540</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2021-06-16T05:55:44Z</dc:date>
    </item>
  </channel>
</rss>

